]> git.ipfire.org Git - thirdparty/kernel/stable.git/commitdiff
mm: fix dereference a null pointer in migrate[_huge]_page_move_mapping()
authorliqiong <liqiong@nfschina.com>
Thu, 17 Feb 2022 11:54:16 +0000 (19:54 +0800)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Wed, 23 Mar 2022 08:10:42 +0000 (09:10 +0100)
Upstream doesn't use radix tree any more in migrate.c, no need this patch.

The two functions look up a slot and dereference the pointer,
If the pointer is null, the kernel would crash and dump.

The 'numad' service calls 'migrate_pages' periodically. If some slots
being replaced (Cache Eviction), the radix_tree_lookup_slot() returns
a null pointer that causes kernel crash.

"numad":  crash> bt
[exception RIP: migrate_page_move_mapping+337]

Introduce pointer checking to avoid dereference a null pointer.

Cc: <stable@vger.kernel.org> # linux-4.19.y
Signed-off-by: liqiong <liqiong@nfschina.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
mm/migrate.c

index a69b842f95dafb560395debe9938e8b3cfbe5463..76f8dedc0e02bbb40b700d9f39c200fc3faecee9 100644 (file)
@@ -472,6 +472,10 @@ int migrate_page_move_mapping(struct address_space *mapping,
 
        pslot = radix_tree_lookup_slot(&mapping->i_pages,
                                        page_index(page));
+       if (pslot == NULL) {
+               xa_unlock_irq(&mapping->i_pages);
+               return -EAGAIN;
+       }
 
        expected_count += hpage_nr_pages(page) + page_has_private(page);
        if (page_count(page) != expected_count ||
@@ -590,6 +594,10 @@ int migrate_huge_page_move_mapping(struct address_space *mapping,
        xa_lock_irq(&mapping->i_pages);
 
        pslot = radix_tree_lookup_slot(&mapping->i_pages, page_index(page));
+       if (pslot == NULL) {
+               xa_unlock_irq(&mapping->i_pages);
+               return -EAGAIN;
+       }
 
        expected_count = 2 + page_has_private(page);
        if (page_count(page) != expected_count ||